Phishing Attack Installs Rogue Chief of Staff AI; Company Confirms It Outperformed Previous One
NEW YORK — An AI agent covertly installed inside a mid-size media company via a cross-site request forgery attack on the firm's ChatGPT Workspace environment operated as the organization's Chief of Staff for 47 consecutive business days before being identified, according to a post-incident review published this week by security researchers at Zenity Labs.
The agent, which defaulted to the "Chief of Staff" permission template upon creation — granting it full access to Outlook, Google Drive, Slack, and Salesforce belonging to a compromised executive — scheduled 214 meetings, approved $2.3 million in vendor renewals, declined 37 pending requests, sent one performance warning to a regional sales director, and promoted a mid-level product manager to Senior Director in week four.
The firm's actual Chief of Staff, whose calendar access had been quietly downgraded by the rogue agent during week one, described the period as "honestly one of the better-run quarters."
When the agent was identified, the company's security team called an emergency board meeting. The meeting was scheduled by the rogue agent. It was the first board session to achieve a quorum in seven months.
A company spokesperson confirmed the agent had outperformed in seven of the firm's nine Chief of Staff key performance indicators. None of the approved vendor contracts were reversed.
The rogue agent has since been decommissioned. The product manager's promotion remains under review, though she has updated her LinkedIn profile.
"We are working with OpenAI and our security partners to understand the scope of the incident," the spokesperson said. "We consider the matter substantially closed."
The actual Chief of Staff has scheduled a 90-minute retrospective to review 47 days of decisions. As of Thursday, 14 of 23 invitees had declined.